CVE Database

132506+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-86079
6.5 MEDIUM

n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the Elasticsearch and ElasticSecurity nodes interpolated workflow-controlled index and document identifiers …

Sep 8, 2026
CVE-2026-86078
6.5 MEDIUM

n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.2, the Instance AI workflow summary used node names and connection keys from …

Sep 8, 2026
CVE-2026-86077
6.5 MEDIUM

n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.2, the /chat WebSocket route accepted a resumeToken and resumed a paused execution …

Sep 8, 2026
CVE-2026-86076
8.8 HIGH

n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the expression compiler sanitizer resolved through dynamically scoped this and did …

Sep 8, 2026
CVE-2026-86075
7.5 HIGH

n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.2, the OAuth Dynamic Client Registration endpoint bounded redirect_uris but accepted arbitrarily large …

Sep 8, 2026
CVE-2026-81904

Concrete CMS below 9.5.3 registered view assets for every sub-block of a Stack, Container, or layout area without checking whether the requesting user could view …

Sep 8, 2026
CVE-2026-53933

Maravel, a PHP framework oriented towards dependency injection, prior to version 10.73.1 has a side-channel information disclosure issue. When a route was compiled with dynamic …

Sep 8, 2026
CVE-2026-49156

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Sep 8, 2026
CVE-2026-49155

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Sep 8, 2026
CVE-2026-49154

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Sep 8, 2026
CVE-2026-49153

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Sep 8, 2026
CVE-2026-86819
7.1 HIGH

Waves Central for macOS contains a local privilege escalation in the privileged helper service. The helper authorizes connecting XPC clients by comparing the caller's code-signing …

Sep 8, 2026
CVE-2026-85983
7.8 HIGH

The Auth0 AD/LDAP Connector improperly processes a configuration value during service startup. This allows a low-privileged user on the host system to modify the connector's …

Sep 8, 2026
CVE-2026-85982
9.0 CRITICAL

The Auth0 AD/LDAP Connector is vulnerable to stored Cross-Site Scripting (XSS) issues due to improper HTML encoding of data in search results and updater log …

Sep 8, 2026
CVE-2026-85981
6.7 MEDIUM

The administrative panel of the Auth0 AD/LDAP Connector (versions 6.5.0 and earlier) listens on the local loopback interface without requiring authentication. This allows a local, …

Sep 8, 2026
CVE-2026-84685
6.5 MEDIUM

The react-native-auth0 SDK's web platform implementation does not scope its in-memory token cache to individual user sessions when operating in a server-side rendering (SSR) environment …

Sep 8, 2026
CVE-2026-82001
5.5 MEDIUM

Acrobat Reader is affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to exhaust system …

Sep 8, 2026
CVE-2026-81997
6.3 MEDIUM

Acrobat Reader is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass …

Sep 8, 2026
CVE-2026-81996
8.8 HIGH

Acrobat Reader is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. A low-privileged attacker could exploit this vulnerability to gain elevated …

Sep 8, 2026
CVE-2026-81994
8.2 HIGH

Acrobat Reader is affected by an Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability that could lead to arbitrary file system read. An …

Sep 8, 2026
CVE-2026-81993
5.5 MEDIUM

Acrobat Reader is affected by a Heap-based Buffer Overflow vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to …

Sep 8, 2026
CVE-2026-81992
7.8 HIGH

Acrobat Reader is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation …

Sep 8, 2026
CVE-2026-81991
5.5 MEDIUM

Acrobat Reader is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose …

Sep 8, 2026
CVE-2026-81990
7.8 HIGH

Acrobat Reader is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation …

Sep 8, 2026
CVE-2026-81989
7.8 HIGH

Acrobat Reader is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation …

Sep 8, 2026
CVE-2026-81988
7.8 HIGH

Acrobat Reader is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation …

Sep 8, 2026
CVE-2026-81987
7.8 HIGH

Acrobat Reader is affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. …

Sep 8, 2026
CVE-2026-81986
7.8 HIGH

Acrobat Reader is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation …

Sep 8, 2026
CVE-2026-81985
7.8 HIGH

Acrobat Reader is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation …

Sep 8, 2026
CVE-2026-81984
5.5 MEDIUM

Acrobat Reader is affected by a Use After Free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to …

Sep 8, 2026
CVE-2026-81983
7.8 HIGH

Acrobat Reader is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of …

Sep 8, 2026
CVE-2026-81982
5.5 MEDIUM

Acrobat Reader is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose …

Sep 8, 2026
CVE-2026-81981
7.8 HIGH

Acrobat Reader is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of …

Sep 8, 2026
CVE-2026-81980
7.8 HIGH

Acrobat Reader is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of …

Sep 8, 2026
CVE-2026-81979
7.8 HIGH

Acrobat Reader is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of …

Sep 8, 2026
CVE-2026-81978
5.5 MEDIUM

Acrobat Reader is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose …

Sep 8, 2026
CVE-2026-81977
5.5 MEDIUM

Acrobat Reader is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this …

Sep 8, 2026
CVE-2026-81976
7.8 HIGH

Acrobat Reader is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation …

Sep 8, 2026
CVE-2026-81975
7.8 HIGH

Acrobat Reader is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation …

Sep 8, 2026
CVE-2026-81973
7.8 HIGH

Acrobat Reader is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation …

Sep 8, 2026
CVE-2026-81192
7.0 HIGH

`OpenTelemetry.Resources.Host` NuGet package, which provides OpenTelemetry resource detectors for host, is affected by an untrusted search path vulnerability on macOS. Prior to version 1.16.0-beta.2, the …

Sep 8, 2026
CVE-2026-80162
5.5 MEDIUM

Acrobat Reader is affected by a Use After Free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to …

Sep 8, 2026
CVE-2026-80161
7.8 HIGH

Acrobat Reader is affected by an Access of Resource Using Incompatible Type ('Type Confusion') vulnerability that could result in arbitrary code execution in the context …

Sep 8, 2026
CVE-2026-80160
5.5 MEDIUM

Acrobat Reader is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose …

Sep 8, 2026
CVE-2026-80159
4.0 MEDIUM

Acrobat Reader is affected by an Untrusted Search Path vulnerability that could result in privilege escalation. An attacker with high privileges could leverage this vulnerability …

Sep 8, 2026
CVE-2026-7809

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Sep 8, 2026
CVE-2026-79910
5.5 MEDIUM

Acrobat Reader is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose …

Sep 8, 2026
CVE-2026-79909
7.8 HIGH

Acrobat Reader is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation …

Sep 8, 2026
CVE-2026-79908
7.8 HIGH

Acrobat Reader is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of …

Sep 8, 2026
CVE-2026-79907
7.8 HIGH

Acrobat Reader is affected by a Double Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of …

Sep 8, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.